CVE-2023-2063: Information disclosure, tampering, deletion and destruction vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP Modules
Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to cause information disclosure, tampering, deletion or destruction via file upload/download. As a result, the attacker may be able to exploit this for further attacks.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-2063.
Which software is affected by this vulnerability?
The Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP are affected.
What is the severity of CVE-2023-2063?
The severity rating for CVE-2023-2063 is 7.3, which is considered high.
What is the impact of this vulnerability?
This vulnerability allows a remote unauthenticated attacker to cause information disclosure and tampering.
Are there any fixes or patches available for this vulnerability?
Please refer to the vendor's website for the latest updates and patches to address this vulnerability.